Skip to main content
SEBI CSCRF · Funds

SEBI CSCRF for AIF and VCF Managers

For AIF and VCF Managers, 3 tiers are reachable, decided by sum of corpus across all AIFs + VCFs + schemes managed (INR crores) and number of clients (sub-100 → M-SOC exemption if self-cert).

Apr 2025 (§2.7): categorisation at the MANAGER level. Sum of corpus across all AIFs + VCFs + schemes managed by the same manager.

Classification

What decides the tier for an AIF and VCF Manager

Alternative funds are categorised at the manager level, with the corpus of every fund and scheme under the same manager summed together. That is a deliberate anti-fragmentation rule: several small vehicles under one manager share the same systems, the same staff and the same email domain, so measuring each in isolation would classify the risk to a fraction of its real size.

Sum of corpus across all AIFs + VCFs + schemes managed (INR crores)

Number of clients (sub-100 → M-SOC exemption if Self-cert)

Obligations

What each reachable tier requires

Only the tiers an AIF and VCF Manager can land in are listed.

Mid-size REs

Stock Brokers 1-10L clients OR ₹1-10L Cr volume, AMCs ₹10k-1L Cr AUM, Custodians ₹1-10L Cr AUC, Portfolio Managers ≥₹10k Cr AUM, AIF+VCF managers >₹10k Cr corpus, RTAs 1-2 Cr folios.

VAPT

Once a year (commences Q1 of FY)

Cyber audit

Once a year (twice a year if providing IBT or Algo trading)

Drill

Annually

  • IT Committee with external cybersecurity expert: mandatory, quarterly meetings
  • 24×7 SOC (own / Market SOC / 3P-managed); annual functional efficacy review
  • HSM: risk-assessed alternative permitted (Board approval required)
  • Designated CISO or equivalent officer
  • Annual cyber resilience posture evaluation (EV.ST.S5)

M-SOC

Eligible for SEBI M-SOC, encouraged

HSM for key storage

Risk-assessed alternative permitted

CISO reporting line

Designated officer is sufficient

IT Committee

Mandatory, meets quarterly

RTO

As set in your CCMP

RPO

As set in your CCMP

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Small-size REs

Stock Brokers 10k-1L clients OR ₹10k-1L Cr volume, AMCs <₹10k Cr AUM, Custodians <₹1L Cr AUC, Portfolio Managers ₹3k-10k Cr AUM, AIF+VCF managers ₹3k-10k Cr corpus, RTAs 10k-1Cr folios, all active Merchant Bankers, Non-individual IAs (registered in another category).

VAPT

Once a year

Cyber audit

Once a year (twice a year if providing IBT or Algo trading)

Drill

Annually

  • Onboard to Market SOC (NSE/BSE): MANDATORY, unless RE has own SOC and submits efficacy reports
  • Designated CISO or equivalent officer
  • IT Committee optional (otherwise MD/CEO/Board approves CSCRF compliance)
  • Annual cyber resilience posture evaluation

M-SOC

Market SOC mandatory unless you run your own

HSM for key storage

Risk-assessed alternative permitted

CISO reporting line

Designated officer is sufficient

IT Committee

Not mandated

RTO

As set in your CCMP

RPO

As set in your CCMP

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Self-certification REs

Stock Brokers 1k-10k clients OR ₹1k-10k Cr volume, Portfolio Managers ≤₹3k Cr AUM, AIF+VCF managers ≤₹3k Cr corpus, CIS, CRAs, Debenture Trustees with new clients in last 3 FYs.

VAPT

Once a year

Cyber audit

Once a year

Drill

Annually

  • Onboard to Market SOC: MANDATORY, unless RE has own SOC
  • Designated CISO or equivalent officer
  • IT Committee optional

M-SOC

Market SOC mandatory unless you run your own

HSM for key storage

Risk-assessed alternative permitted

CISO reporting line

Designated officer is sufficient

IT Committee

Not mandated

RTO

As set in your CCMP

RPO

As set in your CCMP

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Scope

What a CSCRF VAPT has to reach at an AIF and VCF Manager

The capital call is the exposure. It is a legitimate email carrying payment instructions for a large sum to a recipient who expects it, which is the ideal starting position for business email compromise. The manager-level aggregation exists precisely because that risk does not shrink when a manager splits activity across vehicles. Investor data in these vehicles is also unusually sensitive: identifiable individuals with disclosed net worth.

Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what you classify as critical decides how much of the estate gets tested.

Much of an alternatives platform is administrative, and all of it is in scope:

  • The fund administration platform, whether operated in-house or by an administrator
  • Capital call and drawdown workflows, including the notices that carry banking instructions
  • Investor and LP reporting portals, and the data rooms alongside them
  • Subscription, onboarding and e-signature paths
  • Banking and payment interfaces used for calls and distributions
  • Email and document sharing, which at this size is a primary business system rather than a supporting one

Where this goes wrong

Scoping one fund instead of the manager

The framework aggregates at the manager, and so should the assessment. Where the same team, the same mailboxes and the same administrator serve several vehicles, testing one fund and extrapolating produces a result that describes no actual system boundary. The shared services are the system.

Submission

Where an AIF and VCF Manager files, and by when

Reports go to SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.

Within 1 month

Report submitted

The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.

Within 3 months

Findings closed

Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.

Within 5 months

Revalidation complete

Revalidation runs from completion of the VAPT, not from submission, so a cycle started late in the year rarely leaves room to finish it.

Plan the cycle at the start of the financial year, not backwards from the deadline. No audit period may be left unaudited because a category changed mid-year: an unaudited stretch has to be pulled into the current cycle.

How we help

CERT-In empanelled, and the report is written for the submission

We run the VAPT and cyber-audit scope your tier requires, and the report is mapped to the CSCRF control set so it can be filed as written.

Verified against the source circulars as of 3 August 2026.

FAQ

Common questions

These are the questions we are asked most often about this category.

Talk to our team
Does SEBI CSCRF apply to AIF and VCF Managers?+
Yes. AIF and VCF Managers fall under CSCRF. For AIF and VCF Managers, 3 tiers are reachable, decided by sum of corpus across all AIFs + VCFs + schemes managed (INR crores) and number of clients (sub-100 → M-SOC exemption if self-cert).
How often does an AIF and VCF Manager need VAPT under CSCRF?+
At the Mid-size tier: Once a year (commences Q1 of FY). Cyber audit: Once a year (twice a year if providing IBT or Algo trading).
Where does an AIF and VCF Manager submit its CSCRF reports?+
To SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.
Which SEBI circular sets this out?+
As per SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20-Aug-2024 read with CIR/2024/184, CIR/2025/45, CIR/2025/60, CIR/2025/96, CIR/2025/119, the SEBI FAQ (11-Jun-2025), and the May 2026 AI Vulnerability Detection Advisory HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026.